Description
PocketMine-MP versions before 4.2.9 fail to properly validate NBT data types during deserialization of inventory transaction packets from clients. Attackers can send crafted inventory transactions with malformed NBT tags to trigger server crashes and cause denial of service.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Mon, 07 Sep 2026 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | PocketMine-MP versions before 4.2.9 fail to properly validate NBT data types during deserialization of inventory transaction packets from clients. Attackers can send crafted inventory transactions with malformed NBT tags to trigger server crashes and cause denial of service. | |
| Title | PocketMine-MP before 4.2.9 Denial of Service via NBT Deserialization | |
| Weaknesses | CWE-20 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-07T12:55:06.530Z
Reserved: 2026-09-05T21:02:18.431Z
Link: CVE-2022-51012
No data.
Status : Received
Published: 2026-09-07T13:17:23.030
Modified: 2026-09-07T13:17:23.030
Link: CVE-2022-51012
No data.
OpenCVE Enrichment
No data.
Weaknesses
-
CWE-20
Improper Input Validation